This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Visual Studio Code Tunnel Shell Execution
Original Source:
[Sigma source]
Title:
Visual Studio Code Tunnel Shell Execution
Status:
test
Description:
Detects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.
References:
-https://ipfyx.fr/post/visual-studio-code-tunnel/
-https://badoption.eu/blog/2023/01/31/code_c2.html
-https://code.visualstudio.com/docs/remote/tunnels
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2023-10-25
modified:
None
Tags:
-'attack.command-and-control'
-'attack.t1071.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent:
ParentImage|contains
:
'\servers\Stable-'
ParentImage|endswith
:
'\server\node.exe'
ParentCommandLine|contains
:
'.vscode-server'
selection_child_1:
Image|endswith
:
-'\powershell.exe'
-'\pwsh.exe'
CommandLine|contains
:
'\terminal\browser\media\shellIntegration.ps1'
selection_child_2:
Image|endswith
:
-'\wsl.exe'
-'\bash.exe'
condition
:
selection_parent and 1 of selection_child_*
Falsepositives:
-Legitimate use of Visual Studio Code tunnel and running code from there
Level:
medium